Scope definition
Targets, exclusions, test types (external, internal, web, mobile), and success criteria.
A concise proposal reduces ambiguity, aligns expectations, and documents consent for controlled security testing. It helps avoid accidental service disruptions, demonstrates due diligence for audits, and records contractual limits that affect liability and remediation responsibilities.
Organizations preparing for a penetration test often involve technical, legal, and procurement stakeholders to ensure the engagement is safe, compliant, and contractually sound.
A multidisciplinary review helps prevent scope creep, ensures proper authorization, and documents approvals required for safe execution.
Targets, exclusions, test types (external, internal, web, mobile), and success criteria.
Authorized IPs, testing hours, acceptable testing methods, and escalation contacts.
Start/end dates, interim checkpoints, and remediation windows.
Interim findings, final report format, repeatable evidence, and retest options.
Fixed-fee or time-and-materials, change-order terms, and invoicing cadence.
Indemnities, confidentiality, data handling, limitations of liability, and insurance.
| Field | Configuration |
|---|---|
| Scope field | Mandatory multiline textarea with attachment option |
| Test window | Date picker with MM/DD/YYYY validation |
| Approvals | Conditional routing to legal and security reviewers |
| Signatures | Role-based signature fields with date stamps |
Use a platform that preserves an audit trail, supports required file formats, and integrates with your document systems.
Ensure the chosen solution can export a tamper-evident signed file and store metadata such as timestamps, IP addresses, and signer identity.
Date the provider delivers the proposal to the client.
Timeframe for client signature and authorization (commonly 7–21 days).
Authorized period for active testing and agreed time blocks.
Period for client fixes before retest is scheduled.
Delivery date for the assessment report after testing completes.
Provider sends proposal and terms for review.
Authorized signatories accept scope and legal terms.
Active penetration testing within agreed window.
Provider issues findings, evidence, and remediation recommendations.
Optica documented a phased external test to avoid operational impact.
Xerox integrated proposal approvals with NetSuite workflows for procurement.
| Criteria | Pentest Proposal | Vulnerability Assessment |
|---|---|---|
| Interaction level | active exploitation | passive scanning |
| Scope depth | deep, exploit-focused | broad, discovery-focused |
| Operational risk | higher | lower |
| Typical deliverable | exploit evidence and risk narrative | findings list and severity |
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | Yes, 7-day free trial | No | No | Yes, limited | Yes, limited |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |